High severity7.5NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026
CVE-2024-27284
CVE-2024-27284
Description
cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterator after the iterator has advanced to the next item will be accessing freed memory and experience undefined behaviour. The problem has been fixed in version 3.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cassandra-cppcrates.io | < 3.0.0 | 3.0.0 |
Affected products
3- cpe:2.3:a:cassandra-rs_project:cassandra-rs:*:*:*:*:*:rust:*:*Range: <3.0.0
- Metaswitch/cassandra-rsv5Range: < 3.0.0
Patches
Vulnerability mechanics
References
5- github.com/Metaswitch/cassandra-rs/commit/ae054dc8044eac9c2c7ae2b1ab154b53ca7f8df7nvdPatchWEB
- github.com/Metaswitch/cassandra-rs/security/advisories/GHSA-x9xc-63hg-vcfqnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-x9xc-63hg-vcfqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-27284ghsaADVISORY
- rustsec.org/advisories/RUSTSEC-2024-0017.htmlghsaWEB
News mentions
0No linked articles in our index yet.